Mozilla Firefox CVE-2016-1979 Vulnerability

description-logoDescription

Mozilla developer Tim Taubert used the Address Sanitizer tool and software fuzzing to discover a use-after-free vulnerability while processing DER encoded keys in the Network Security Services (NSS) libraries. The vulnerability overwrites the freed memory with zeroes. This issue has been addressed in NSS 3.21.1, shipping in Firefox 45.

affected-products-logoAffected Applications

Firefox

CVE References

CVE-2016-1979